Risk categories
Grouping by risk means you reason about blast radius, not about individual features. Creating an internal ticket and sending a customer an email are both “creating something” — but they deserve very different rules.
Defaults are safe out of the box: a freshly connected tool lets agents read, asks a human before changing anything, and keeps dangerous capabilities off. Some integrations suggest stricter defaults that fit their nature.
For the highest-risk categories — payments, destructive actions, public publishing, administration — Allow is not available. The most you can grant is Ask approval: a human is always in the loop for these.
Replying doesn’t need a permission slip. By default, an agent may answer in the conversation it was called in — the Slack thread, the email thread — without approval. Messaging any other destination follows the External communication verdict. You can turn this exception off per connection.
Per-action exceptions
The category verdict is usually all you need. For specific cases, you can override a single action: allow one routine write while the rest of the category asks for approval, or shut off one action entirely. Exceptions follow the same rule as everything else — they can loosen within limits, but the high-risk categories still never reach plain Allow.How approvals work
When an agent reaches an action that requires approval, it doesn’t do it — it asks:- The run pauses and an approval request is created, showing what the agent wants to do and with which tool.
- Approvers are notified. By default,
OwnerandAdmincan approve; approval policies can route specific decisions to specific people or teams. - Approve and the agent continues exactly where it stopped. Deny and the agent moves on without the action, telling the person it’s working with.
Auditing
Every action an agent takes, every approval decision, and every change to permissions is recorded — what happened, who decided, and when. Changes to permissions take effect immediately. Permissions are managed byOwner and Admin roles, per connection, in Integrations → the connection → Agent permissions.